Hackers Exploit PaperCut Vulnerabilities for Data Theft

Photo: BleepingComputer
Quick answer
Hackers are leveraging two critical PaperCut NG/MF vulnerabilities to steal data from servers. The vendor has issued urgent patches, but attacks are already in progress.
PaperCut Software, the developer behind the widely used PaperCut NG and MF print management solution, has reported a large-scale attack campaign exploiting two recent vulnerabilities. The software is deployed by over 70,000 organizations, including major corporations, government agencies, and educational institutions, serving a total user base exceeding 100 million.
Tracked as CVE-2026-81578 and CVE-2026-82078, these vulnerabilities enable threat actors to bypass authentication and gain remote access to PaperCut servers. Unlike prior attacks focused on arbitrary code execution, this campaign specifically targets data theft, particularly extracting database contents through a vulnerable external user search mechanism.
The company has released three urgent patches over several days, starting August 29, to mitigate risks for customers whose servers cannot be temporarily disconnected from the internet. PaperCut CEO Chris Dance noted that initial patches were temporary measures, with subsequent versions incorporating additional protections as new threat details emerged.
Cybersecurity experts at Defused have confirmed active exploitation of these vulnerabilities in real-world attacks. According to Shadowserver, over 800 PaperCut servers remain exposed online, some of which may serve as decoys for attackers. PaperCut has published indicators of compromise to help security teams identify potential incidents.
PaperCut has previously been targeted by cybercriminals. In 2023, similar vulnerabilities were exploited by groups like LockBit, Clop, Muddywater, and APT35, as well as for distributing the Bl00dy ransomware. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also repeatedly warned about the risks of exploiting vulnerabilities in this software.
Common questions
- Which PaperCut vulnerabilities are being exploited?
- Two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, allow attackers to bypass authentication and steal data from PaperCut NG and MF servers.
- Have any organizations already been affected?
- Real-world attacks have been confirmed, though specific victims and damage scales remain undisclosed. Experts note increased activity in honeypot systems.
- How can users protect themselves?
- PaperCut has released three urgent patches, with the latest (Release 3) recommended for all users, especially those with internet-facing servers.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml